This software implements concepts from the Factor Analysis of Information Risk (FAIR) methodology and the FAIR Controls Analytics Model (FAIR-CAM), frameworks for cyber risk quantification and control effectiveness analysis.
FAIR, FAIR-CAM, and the FAIR Institute logo are registered trademarks of the FAIR Institute.
- NOT affiliated with the FAIR Institute
- NOT endorsed by the FAIR Institute
- NOT certified by the FAIR Institute
- An independent implementation created for research purposes
For official FAIR training, certification, and authoritative resources:
- FAIR Institute: https://www.fairinstitute.org/
- FAIR Training and Certification: https://www.fairinstitute.org/fair-training-and-certification
This implementation follows the FAIR-CAM specification as documented in:
- "Measuring and Managing Information Risk: A FAIR Approach" by Jack Jones and Jack Freund
- The FAIR-CAM technical standard published by the FAIR Institute
Any deviations from or extensions to the standard FAIR-CAM methodology are documented in the accompanying paper and in this repository.
This repository incorporates benchmark data from:
IRIS 2025 (Information Risk Insights Study)
- Author: Cyentia Institute (https://www.cyentia.com/)
- Access: Available at https://www.cyentia.com/iris2025/
- Usage: Statistical parameters extracted with full source attribution
- Purpose: To aid community efforts to manage cyber risk
Full Citation: Cyentia Institute. (2025). Information Risk Insights Study 2025: It's About Time. Sponsored by the Cybersecurity and Infrastructure Security Agency (CISA). Retrieved from https://www.cyentia.com/iris2025/
Users must comply with the respective licenses and terms of use for all data sources.
For questions about:
- The FAIR/FAIR-CAM methodology itself: Contact the FAIR Institute
- This specific implementation: Open an issue in this repository